Multi-tenant security & secure-edge platform

Your whole security stack, in one console.

OneNetSpace unifies endpoint detection, secure edge networking, web & DNS filtering, data-loss prevention, cloud app visibility, vulnerability management, patching, and compliance — so MSPs and IT teams stop stitching five vendors together and manage every customer or site from one screen.

One console · Multi-tenant by default · Onboard in minutes, not weeks

OneNetSpace operations dashboard: device fleet health, open findings, patch status, security posture score, per-feature license usage, and a live network topology of every site's tunnel to the secure edge.
Replaces a drawer full of point tools
The platform

One platform, four domains, sixteen-plus modules

Every capability shares one agent, one data model, and one multi-tenant console — so a policy change, an alert, and an audit answer all live in the same place.

Endpoint

  • EDR — behavior-based detection, auto-kill, auto-isolate, forensic timelines
  • Vulnerability scanning — MITRE ATT&CK + CVE checks, CISA KEV correlation
  • Patch management — visibility, scheduling, and verification
  • Asset inventory — hardware, software, and IoT discovery
  • BitLocker key escrow — encrypted, MFA-gated recovery keys
  • Remote control — assist endpoints without a second tool

Secure edge

  • Zero-trust tunnels — always-on, identity-aware path to a managed PoP
  • Web & DNS filtering — category blocking + DNS sinkhole at the edge
  • Intrusion prevention — inline IDS/IPS on tunneled traffic
  • TLS inspection — opt-in, per-tenant certificate authority
  • Site gateways — branch & on-prem connectivity, split or full tunnel
  • Threat intelligence — curated feeds enforced at the edge

Data & cloud

  • Data-loss prevention — pattern + context detection on data in motion
  • Cloud app visibility (CASB) — discover & risk-score every SaaS in use
  • Secure browser — managed, policy-enforced browsing
  • Shadow-IT discovery — surface unsanctioned apps before they're a finding
  • Per-app policy — allow, warn, or block by application and category

Governance

  • Compliance mapping — CMMC 2.0, NIST 800-171, HIPAA, PCI, and more
  • Signed audit logs — per-decision, per-operator, per-tenant retention
  • SIEM export — stream events to the SIEM you already run
  • Reporting — board- and auditor-ready summaries
  • Identity & directory — sync users and groups from your IdP
  • Release control — stable/beta channels and version pinning
Inside the console

See the actual product

No mockups. This is the console your team — or your customers — log into every day.

Operations dashboard with fleet health, findings, patch status, posture score, license usage, and a live multi-site network topology.

A live operations dashboard

Fleet health, open findings by severity, patch backlog, posture score, and per-feature license usage — refreshed continuously. The network-topology map shows every site's tunnel state to the secure edge at a glance, scoped to one customer or all of them.

CVE scan dashboard: actively-exploited CVEs from the CISA KEV catalog, ransomware correlation, findings trend over time, and MITRE ATT&CK-mapped detection rules.

Vulnerability management that prioritizes itself

Findings are correlated against the CISA Known-Exploited-Vulnerabilities catalog and ransomware associations, then mapped to MITRE ATT&CK — so "what do I fix first" is answered before you ask. Agents evaluate checks locally; the console shows the trend.

Compliance assessment for CMMC 2.0 / NIST 800-171: per-control status, evidence, and an overall readiness score with export to PDF.

Compliance you can hand to an auditor

Map your posture to CMMC 2.0, NIST 800-171, HIPAA, PCI, and other regimes. Each control shows status and supporting evidence, with an overall readiness score and one-click export — turning "are we compliant?" into a document instead of a fire drill.

16+integrated modules, one agent
1,600+actively-exploited CVEs tracked (CISA KEV)
MITREATT&CK-mapped detections
Minutesto onboard a new tenant or site
Who it's for

Built for the way you actually operate

For Managed Service Providers

Multi-tenant from the ground up. Every customer gets isolated policy, isolated data, and isolated decryption keys, all managed from one provider console. Onboard a new tenant in under an hour and roll changes across your customer base without rebuilding stacks.

  • True multi-tenant data plane
  • Per-customer branding and policy
  • Provider access with a full audit trail
  • Pre-scoped installers your customers self-deploy
  • One bill, one renewal, one vendor relationship

For enterprise IT and security teams

One platform replaces the EDR + VPN + web filter + CASB + vuln-scanner stack you've assembled over the years. Manage every site, business unit, and acquisition from a single console without carrying five vendor relationships and five renewal cycles.

  • Single console across all sites and BUs
  • Identity-aware policy from endpoint to cloud
  • Granular per-team rule sets and exceptions
  • Compliance mapping for the regimes you answer to
  • Integration paths for your existing IAM and SIEM
How it works

From install to enforcement in three steps

No professional-services engagement, no week-long stand-up. Three steps and you're operating.

  1. 1

    Deploy the agent

    One installer per device. Self-enrolls against the customer or site you scoped it to. Windows today; macOS and Linux on the roadmap.

  2. 2

    Tunnel up to the edge

    The agent brings up an always-on encrypted path to the nearest point of presence. Identity-aware policy is applied at the edge before traffic ever leaves your network.

  3. 3

    Manage from one console

    Tune policy, review alerts, audit decisions, and onboard new tenants or sites — all in one browser tab. Roll changes to one customer or every customer with a single click.

Trust

Designed around customer trust

Tenant data stays separated

Hard isolation at every layer — data plane, control plane, and decryption keys. Cross-tenant access requires explicit, audited, time-limited grants.

Decryption is opt-in

TLS decryption is a per-tenant feature with per-tenant certificate authorities. Tenants who can't or won't decrypt simply don't — visibility degrades gracefully without breaking enforcement.

Auditable by default

Every administrative action and traffic decision is logged with operator identity and per-tenant retention. Your auditors can answer "who did what" without ticket archaeology.

Hardened by design

Enforced MFA for administrators, secrets encrypted at rest, least-privilege containers, and continuous dependency scanning in the release pipeline.

Predictable change

Stable and beta release channels. Pilot users you control. Approved-version pinning so a Friday afternoon never becomes a rollout incident.

Cloud-agnostic edge

Points of presence run on any provider or your own hardware — no lock-in to a single cloud's egress, and you place capacity where your users actually are.

See it on your own traffic

A 30-minute walkthrough on a real workload — your endpoints, your sites, your policy questions. We'll show you how OneNetSpace replaces the stack you have today and where it changes the operating model.